Azure-Samples / Azure-Samples/openai

Azure AI Foundry – LLM Translator: Bearer Token Authentication Fails, Subscription Key Works

Open
#179 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Jupyter Notebook
Stars
1.3k
Forks
455
Avg merge
16h 17m
Merged PRs (30d)
1

Description

**Problem Description**
I am using Azure AI Foundry and the Translator LLM endpoint (api-version=2025-10-01-preview) with deploymentModel.
When I use a Subscription Key, the request works as expected. However, when I use an AAD Bearer Token (Audience https://cognitiveservices.azure.com/.default), I receive:
{"code":"401","message":"Ocp-Apim-Subscription-Key is missing"}
{"error":{"code":401001,"message":"The request is not authorized because credentials are missing or invalid."}}

Expected behavior: Access with Bearer Token without Subscription Key, as described in the Preview documentation.

**What I Have Already Done**
Created an App Registration in Microsoft Entra ID.
Added API permission Microsoft Cognitive Services → user_impersonation and granted Admin consent.
Requested token with scope https://cognitiveservices.azure.com/.default.
Verified token claims (Audience and Tenant are correct).
(This is working fine for month now with the conventional Azure Translator and AI Services)

Created Foundry resource and project, established connection

Assigned RBAC roles:
Cognitive Services User on the Foundry(Translator) resource.
Azure AI User on the Foundry Project.
Contributor on the Resource Group.

**Endpoint:**
https://.cognitiveservices.azure.com/translator/text/translate?api-version=2025-10-01-preview

**Request Body (example):**
"{\"inputs\":[{\"text\":\"Text to be translated\",\"language\":\"de\",\"targets\":[{\"language\":\"it\",\"deploymentName\":\"gpt-4o-trans-llm\"}]}]}"

**Request Headers:**
Authorization: Bearer
Content-Type: application/json

**Response**
**Error Code: 401 Unauthorized – Ocp-Apim-Subscription-Key is missing**

**Tested with Subscription Key → works fine.**

Questions:
Did I forget something?
Is Bearer Token fully supported for LLM Translator Preview?
Are there additional roles or Entra ID settings required?
Could this be a bug in the Preview implementation?

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the documented LLM Translator preview request at the listed endpoint, comparing the working subscription-key request with the Bearer-token request and its headers. Check the preview authentication documentation and the assigned Entra ID/RBAC settings; done means establishing whether Bearer tokens are supported or identifying the missing configuration or implementation defect.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
api, authentication, cloud
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.